What is this?

This knowledgebase contains questions and answers about PRTG Network Monitor and network monitoring in general.

Learn more

PRTG Network Monitor

Intuitive to Use. Easy to manage.
More than 500,000 users rely on Paessler PRTG every day. Find out how you can reduce cost, increase QoS and ease planning, as well.

Free Download

Top Tags


View all Tags

Filtering netflow sensor data to include outside interface only

Votes:

0

I have a Cisco-ASA5505 firewall setup to send Netflow data to a Netflow v9 sensor on my monitoring workstation. This is working correctly (I am getting sensor data) but I only want to see stats on the packets arriving on/leaving my "outside" interface. My Cisco box litterally calls the interface between it and my ISP the "outside" interface and I have it configured as VLAN2.

Below are the include filters I tried to use in the sensor's "Settings" tab none of them worked. I.e. I stopped seeing data after defining the filter. Once I removed the filter data started appearing again. What is the correct syntax for using the "Interface" and "VLAN" filter fileds? Or perhaps I should be using a different filter field?

Filter used:

Interface[outside] VLAN[2]

Please note that I do not want to configure my ASA to restrict the netflow stats to a particular interface because I want the ability to inspect inside interface (LAN) traffic on a different probe.

Thanks

asa-firewall filter netflow

Created on Nov 29, 2012 6:08:21 PM



1 Reply

Votes:

0

Hello,

the Interface[ ]-filter only works with numerical entries. You can try enabling the "Log Stream Data to Disk"-option in the sensor, then check the generated CSV file, it should contain the interface-fields and their content.

best regards.

Created on Nov 30, 2012 2:16:08 PM by  Torsten Lindner [Paessler Support]




Disclaimer: The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.